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Defense and Congress; and informs the public. 


Vision 

Our vision is to be a model oversight organization in the Federal 
Government by leading change, speaking truth, and promoting 
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professional team, recognized as leaders in our field. 
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Results in Brief _ 

(U//rOUC) Combat Mission Teams and Cyber Protection 
Teams Lacked Adequate Capabilities and Facilities to 
Perform Missions 


(U) Finding (cont'd) 


(U) Objective 

(U) We determined whether Cyber Mission 
Force (CMF) teams had adequate facilities, 
equipment, and capabilities to effectively 
perform missions. 

(U) Finding 
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ARMY; NAVY; USAF; (D)(1), Sec. 

1.4(g) 



• (U/ / ‘ HW0j Army Cyber Command did not provide adequate 



(U) Management Actions Taken 



5E3IARMY; NAVY; USAF; USMC: (b)( 1), Sec. 1.4(g) 


(U) Recommendations 

(U) We recommend that the Chiefs of Staff, U.S. Army and U.S. Air Force; 
the Chief of Naval Operations; the Commandant of the Marine Corps; and 
the Commander, USCYBERCOM: 

• (U) develop or update a doctrine, organization, training, materiel, 

leadership and education, personnel, facilities, and policy 
framework to document capability requirements and associated 
capability gaps to build the current force, grow and mature the 
full CMF, and develop and sustain CMF capabilities, and 
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Results in Brief _ 

(U//FOUC) Combat Mission Teams and Cyber Protection 
Teams Lacked Adequate Capabilities and Facilities to 
Perform Missions 


• (U) formalize an agreement to focus 
capability development on functional 
and mission areas consistent with the 
results of the CMF mission alignment 
board to begin identifying capability 
gaps and developing capabilities that 
affected these proposed missions. 

(U) We also recommend that the 
Commander, USCYBERCOM develop and 
specify the capability baseline and 
interoperability standards for CPTs. In 
addition, we recommend that the 
Commander, Army Cyber Command and 
Second Army develop a time-sensitive plan 
of actions and milestones to provide all 
Army CPTs with adequate workspace and 
consistent classified network access. 

(U) Management 
Comments and Our 
Response 

(U) We did not receive comments from the 
Chief of Staff for the Air Force and the 
Commandant of the Marine Corps in 
response to the draft report. Comments 
from the Chief of Naval Operations; Deputy 
Chief of Staff for the U.S. Army; and 
Commander, Army Cyber Command and 
Second Army, addressed the specifics of the 
recommendations. Comments from the 
Commander, USCYBERCOM, partially 
addressed the specifics of the 
recommendations, but further comments 
are required. We request management 
comment on the final report no later than 
December 24, 2015. Please see the 
Recommendations Table on the next page. 
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(U) Recommendations Table 


Unclassified 

Management 

Recommendations 

Requiring Comments 

No Additional 

Comments Required 

Chief of Staff, U.S. Army 


1,2 

Chief of Naval Operations 


1,2 

Chief of Staff, U.S. Air Force 

1,2 


Commandant of the Marine Corps 

1,2 


Commander, U.S. Cyber Command 

1 

2,3 

Commander, U.S. Army Cyber 
Command and Second Army 


4 

Unclassified 


(U) Please provide Management Comments no later than December 24, 2015. 
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INSPECTOR GENERAL 
DEPARTMENT OF DEFENSE 
4800 MARK CENTER DRIVE 
ALEXANDRIA, VIRGINIA 22350-1500 


November 24, 2015 


(U) MEMORANDUM FOR DISTRIBUTION 

(U// FOUO) SUBJECT: Combat Mission Teams and Cyber Protection Teams Lacked Adequate 
Capabilities and Facilities to Perform Missions 
(Report No. DODIG-2016-026) 

(U/ / i FO i l!>Q i ) We are providing this final report for review and comment. U.S. Cyber Command, the 
Service Components, and the Defense Information Systems Agency made progress in providing 
Cyber Mission Force Teams with facilities, equipment, and capabilities to perform missions but did 
not take sufficient steps to ensure all teams had adequate capabilities and facilities. Specifically, 
U.S. Cyber Command, the Service Components, and the Defense Information Systems Agency lacked 
a unified approach to ensure Combat Mission Teams and Cyber Protection Teams had adequate 
capabilities to perform offensive and defensive missions. Additionally, Army Cyber Command did 
not provide select Army Cyber Protection Teams with adequate workspace or facilities to access 
needed networks. We conducted this audit in accordance with generally accepted government 
auditing standards. 

(U) We considered management comments on a draft of this report when preparing the final 
report. However, the Chief of Staff for the U.S. Air Force and the Commandant of the Marine Corps 
did not comment on Recommendations 1 and 2. DoD Instruction 7650.03 requires that 
recommendations be resolved promptly. Therefore, we request the Chief of Staff and the 
Commandant provide comments on the recommendations no later than December 24, 2015. 

(U) Comments from the Commander, U.S. Cyber Command, addressed the specifics of 
Recommendation 2 and 3; however, the Commander partially addressed Recommendation 1. 
Comments from the Director, Warfare Integration, responding for the Chief of Naval Operations, 
and the Chief, Cyberspace and Information Operations Division, responding for the Chief of Staff for 
the U.S. Army, addressed the specifics of Recommendations 1 and 2. We request the Commander, 
U.S. Cyber Command, provide additional comments on the final report no later than December 24, 
2015. Although not required to comment, the Commander, Marine Corps Forces Cyber Command 
and the Chief of Staff, Air Forces Cyber Command, generally agreed with the finding and 
recommendations. 


S E€RET/ - /NOFORN 


i>oim;-20Ui-02(i|iv 





SECRET/ ' /NQFQR ' N ' 


(U) Please provide comments that conform to the requirements of DoD Instruction 7650.03. 
Classified comments must be sent electronically over the Secret Internet Protocol Router Network 


(SIPRNet). Please send a PDF file containing your comments tc 
and 


DoD OIG: (b)(6) 


@dodig.smil.mil 


DoD OIG: (b)(6) 


l @dodig.smil.mil . Copies of your comments must have the actual signature of the 
authorizing official for your organization. We cannot accept the /Signed/ symbol in place of the 
actual signature. Comments provided on the final report must be marked and portion-marked, as 
appropriate, in accordance with DoD Manual 5200.01. If you consider any matters to be exempt 
from public release, you should mark them clearly for Inspector General consideration. 


(U) We appreciate the courtesies extended to the staff. Please direct questions to me at 
(703] 699-|m| (DSN 499f|||]. 


Carol N. Gorman 
Assistant Inspector General 
Readiness and Cyber Operations 
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(U) DISTRIBUTION: 

(U) DEPUTY ASSISTANT SECRETARY OF DEFENSE FOR CYBER POLICY 
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(U) COMMANDER, U.S. CYBER COMMAND 
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(U) Introduction 

(U) Objective 

(U) Our audit objective was to determine whether Cyber Mission Force (CMF) teams 
had adequate facilities, equipment, and capabilities 1 to effectively perform mission 
requirements. See Appendix A for the, scope and methodology and prior audit coverage 
related to the objective. 

(U) Background on DoD Cyberspace Operations 

(U) DoD uses cyberspace to enable its military, intelligence, and business operations. 
Cyberspace is one of the five DoD domains; the other domains are air, land, maritime, 
and space. Cyberspace, unlike the other physical domains, is a global domain within the 
information environment that consists of interdependent networks of information 
technology infrastructures and resident data. Cyberspace operations ensure access and 
freedom of operations in, through, and from cyberspace to deliver effects 2 in any of the 
five domains; to deny adversaries access and freedom of operations; and to sustain 
mission essential segments of cyberspace (networks) in the face of adversary action. 
Cyberspace operations are categorized under three lines of operations, based on their 
intent: 

1. (U/ /FOUO) Offensive Cyberspace Operations. Project power by the 
application of force in and through cyberspace. 

2. (U/ /FWQ) Defensive Cyberspace Operations. Defend DoD or other 
friendly cyberspace. 

3. (U/ / ' F<3lj#) DoD Information Network (DoDIN) Operations. Design, build, 
configure, secure, operate, maintain, and sustain DoD communications systems 
and networks. 


1 (U/ /i~0 'fe ) e) A cyber capability is a device, computer program, or technique—including any combination of software, 
firmware, and hardware—designed to create an effect in or through cyberspace. 

2 (U) Cyber effects include manipulating, disrupting, denying, degrading, or destroying information or communications 
systems, networks, physical or virtual infrastructure controlled by computers or information systems, or information 
resident on the infrastructure. 


GCCRCT//NOTORN 


nnnif.-2tH6-()Zf.| i 







SECRET//NOFORN 


(U) Introduction 


(U) CMF Development 


a gj:!^5:J;5ia5^da ARMY;NAVY; USAF; USMC: (b)(1). Sec. 1.4(g) 


fc /WMtuuaasmsatlamMsa 


'•) Table 1. 


IARMY; NAVY: USAF; USMC: (h)(1). Sec. 1.4(g) 
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IARMY; NAVY; USAF; USMC: (b)( 1), Sec. 1.4(g) 


* (U) The Commander, Cyber National Mission Force, commands and controls National Mission Teams and National Support 
Teams to defend the nation in response to foreign hostile action or imminent threats in cyberspace. 


3 (U) Figures presented in this report are rounded amounts. 
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(IJ) Introduction 




(U) Cyberspace Responsibilities and Requirements 

(U) Under the authority of the Secretary of Defense, DoD uses cyberspace capabilities to 
perform integrated offensive and defensive operations. The Deputy Assistant Secretary 
of Defense for Cyber Policy, Office of the Under Secretary of Defense for Policy: 


• (U] integrates cyberspace operations into national and DoD strategies; 

• (U] develops policy related to cyber forces and employment of those forces; and 

• (U] ensures cyber capabilities are integrated into operation and 
contingency plans. 


4 (U) Additional information on the fielding of CMF teams is described in DoD 01G Report DODIG-2015-117, "USCYBERCOM 
and Military Services Need to Reassess Processes for Fielding CMF Teams," April 30, 2015 (S//NF). 
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(IJJ liHroduetion 


(U) The Chairman of the Joint Chiefs of Staff ensures cyberspace plans and operations 
are compatible with other military plans. Although the Commander, U.S. Strategic 
Command is required to secure, operate, and defend the DoDIN and critical cyberspace 
assets, systems, and functions against an intrusion or attack, the Commander delegated 
most cyberspace responsibilities to the Commander, USCYBERCOM. The Commander, 
USCYBERCOM has three mission areas to counter threats to the DoDIN and military 
operations and to enable offensive cyberspace operations: 

• (U) defend the Nation; 

• (UJ support Combatant Command contingency and operational planning; and 

• (U) support the security, operation, and defense of the DoDIN. 

(U) Additionally, USCYBERCOM: 

• (U) develops a master implementation plan and schedule to accelerate the 
CMF build; 

• (U) coordinates and prioritizes capability development across the Service 
Components and funds capabilities supporting joint requirements; 

• (U) maintains the reliability of the cyber capabilities registry (CCR); 5 and 



5 (3;7H E L T 8U3ft, T V E'I 1 ) 
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(II) I ill roduction 


• (U// TOUO) The other combatant commanders operate and defend their tactical 
and constructed networks and integrate cyberspace capabilities into all military 
operations. As such, combatant commanders are required to integrate 
cyberspace capabilities into their command plans and coordinate with other 
combatant commanders, the Service Components, and DoD agencies to create 
fully integrated capabilities. 


(U) To support combatant commanders, Service Components staff, train, and 
equip forces and secure and defend their global networks. Additionally, the 
Service Components: 

• (U) analyze missions and provide facilities for non-national CPTs; 

• (U) coordinate with combatant commanders to locate combatant 
command CPTs; 

• (U/ /rOUO) identify capability gaps and requirements through their Joint Force 
Headquarters-Cyber {JFHQ-CJ 7 and develop capabilities to support 
Service-specific and other .joint capabilities when funded; 

• (U) program, budget, maintain, and develop materiel solutions (for example, 
deployable toolkits) to meet CPT defensive capability needs; and 

• (U) assist USCYBERCOM to determine CMF mission alignment. 


ARMY; NAVY; USAF; USMC: (b)(1). Sec. 



7 (U/ /fOWi> ) The four JFHQ-C components (ARCYBER, FLTCYBER, AFCYBER, and MARFORCYBER) command and control the 
CMTs that conduct offensive operations in direct support of the combatant commands. 

GECRET//NQFORN 
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(U) The NSA: 


• (U// P Q I 4 Q - ) provides workspace for NMTs, NSTs, CMTs, CSTs, and national CPTs 

through leased facilities, new construction, or renovations to existing NSA 
cryptologic centers; 




( S//RCL TO USA, rVCV) 


ARMY; NAVY; USAF; USMC: (b)(1), Sec. 1.4(g) 



• (U) develops or modifies capabilities to support CMTs. 


(U//F0W6) The Director, Defense Information Systems Agency (DISA), as the 
Commander, JFHQ-DoDIN, plans, directs, coordinates, integrates, and synchronizes the 
execution of missions that defend DoD networks. The Commander, JFHQ-DoDIN, 
develops agreements with Service Components to locate (provide facilities) and equip 
DoDIN CPTs. 


(U) Review of Internal Controls 


(U) DoD Instruction 5010.40, "Managers' Internal Control Program Procedures," 

May 30, 2013, requires DoD organizations to implement a comprehensive system of 
internal controls that provides reasonable assurance that programs are operating as 
intended and to evaluate the effectiveness of the controls. We identified internal 
controls weaknesses at USCYBERCOM. 


ARMY; (b)(7)(E) 



responsible for internal controls at USCYBERCOM, ARCYBER, FLTCYBER, AFCYBER, and 


MARFORCYBER. 
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(U) Finding 


(U) Finding 

(U//F9U0) Capabilities and Facilities for CMTs and 
CPTs Were Inadequate 




• (U// F0U0) ARCYBER did not provide adequate temporary facilitiesjj|yjjj^|||^ 



8 (U/ /H3 H Q) Subject matter experts are responsible for tracking the progress of capability development throughout its 
lifecycle and completing operational testing and evaluation. USCYBERCOM refers to subject matter experts as tool 
champions. 
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(I)) Finding 



(U) CMF Teams Had Adequate Desktop Equipment 


(U// FOUO) USCYBERCOM, the Service Components, and DISA adequately equipped 
CMF teams with desktop equipment to perform administrative and mission 
requirements 10 with the exception of ARCYBER CPTs located 

and a FLTCYBER CMT. USCYBERCOM, in 
coordination with the Service Components, developed desktop equipme nt baselines to 
support the Service Components and DISA in equipping the CMF teams. 


ARMY: (b)(7)(E) 


ARMY: (b)(7)(E) 


ARMY: (b)(7)(E) 


(U/ /POUO) j_ 

| See Appendix A for the teams 
visited. Although only AFCYBER developed a written implementation plan, ARCYBER, 
FLTCYBER, MARFORCYBER, and DISA established deliberate processes to equip CMF 
teamsThe Service Components and DISA either 
used the USCYBERCOM baseline to equip teams or equipped teams with similar desktop 
configurations based on established Component missions, internal collaboration with 
Service Component organizations, or a combination of the two approaches. In general, 
workstations included monitors and peripheral devices, classified and unclassified 
communication systems, and access to the Non-secure Internet Protocol Router 


9 (U) An integrated approach is based on a Doctrine, Organization, Training, Materiel, Leadership and Education, Personnel, 
Facilities, and Policy framework. 


10 /g/ZhirJ 1 

ARMY: NAVY: USAF: USMC: (bm Sec. 1.4(e) 

1 

■ 




11 We discussed this issue further in the "Temporary Army CPT Facilities Provided Inadequate Workspace and 

Network Access" section of this report. 
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(U) Finding 




IARMY; NAVY; USAF; USMC: (b)( I), Sec. 1.4(g) 



(U) Unified Strategy and Approach for Offensive 
Capability Development Was Needed 

(U// HW 3 ) Service Components continued to use Component-specific approaches and 
strategies to develop offensive capabilities that aligned to traditional Component- 
specific mission areas rather than unify capability development to support the CMTs. 
This occurred because USCYBERCOM did not have appropriate authorities to effectively 
oversee and direct offensive capability development. Although USCYBERCOM 
developed the Cyber Force Concept of Operations and Employment 12 and Integrated 
Master Plan and Schedule and established the Integrated Capabilities Requirements 
Working Group and the CCR, these initiatives left gaps in unifying offensive 
capability development. 


(U) The Government Accountability Office (GAO) reported that the Service Components 
used separate, service-specific approaches to identify and meet capability 
requirements. 13 Consequently, GAO concluded that capabilities may vary across the 
Service Components. GAO recommended DoD develop and publish detailed policies and 
guidance that: 


• (U) affect the categories of personnel who perform cyberspace operations; 

n 1 ‘’' 

• (U) support command and control relationships between USCYBERCOM and 
combatant commanders; and 

• (U) address mission requirements and capabilities for the Service Components 
to meet to provide long-term operational support to USCYBERCOM. 


(U) As of July 2015, two of the three recommendations were closed; the 
recommendation related to the categories of personnel remained open. Although GAO 
reported that the differences between the Components might be expected, it also 


12 (U) USCYBERCOM Cyber Force Concept of Operations and Employment, Version 4.1, July 22, 2014 (S//RELTO USA, FVEY). 

13 (U) GAO-11-421, "More Detailed Guidance Needed to Ensure Military Services Develop Appropriate Cyberspace 
Capabilities," May 2011. 
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(U) Finding 


(U) questioned whether these differences were beneficial and whether the Service 
Components would be able to meet long-term capability requirements. 


(U) Service-Specific Offensive Capability Development 
Processes Were Not Coordinated 


NAVY; USAF; USMC: (b)( 1), Sec. 1.4(g) 



14 (U) Concept of Operations for the JFHQ-C, Version 2.0, May 1, 2014 (S//REL TO USA, FVEY). 


15 (G//RCL TO UGAj rWLV ) 


ARMY; NAVY; USAF; USMC: (b)(1), Sec. 1.4(g) 


16 (U) ARCYBER and Second Army Strategy for Defining Operational Requirements and Acquiring Capabilities, Version 2.2, 
October 22, 2012 (updated November 20, 2012) (S//NF). 
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(LI) Finding 



I 



(U) USCYBERCOM Actions Were Insufficient to Unify 
Capability Development 

(U // FOUO) USCYBERCOM is the focal point for all DoD cyberspace operations. 
Specifically, USCYBERCOM: 

• (U) identifies and prioritizes technical capability requirements; 

• (U) monitors development of proposed technology solutions and architectural 
frameworks and associated interoperability standards; 

• (U) oversees development of advanced tactics, techniques, and procedures to 
employ capabilities; and 

• (U) oversees test and evaluation of cyberspace capabilities. 

(U/ /rOUO) To meet its responsibilities, USCYBERCOM developed the Integrated Master 
Plan and Schedule, the Cyber Force Concept of Operations and Employment, established 
processes and the Integrated Capabilities Requirements Working Group to facilitate 
capability development, and created the CCR; however, these initiatives did not ensure 
a unified and coordinated approach to CMF capability development. 
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(il) Finding 


(UJ Components responsible for 
implementing the force did not 
have a comprehensive 
DOTMLPF-P framework. 


(U) Cyber Capability Framework Was Lacking 

(U) Although DoD was more than 2 years into the 
CMF build as of September 2015, the Components 
responsible for implementing the force did not 
have a comprehensive doctrine, organization, 
training, materiel, leadership and education, personnel, facilities, and policy 
(DOTMLPF-P) framework to guide CMF implementation. An integrated approach such 
as a DOTMLPF-P framework was needed to document capability requirements and 
associated capability gaps to build the current force, grow and mature the full CMF, and 
develop and sustain CMF capabilities. Guidance from many sources, including a 
DOTMLPF-P framework, influences military operations, intelligence activities, 
development and validation of capability requirements, acquisition activities affecting 
organization, training, and equipping forces, and the budget process to fund these 
activities. 


(U) USCYBERCOM and the Joint Staff developed the Integrated Master Plan and 
Schedule to describe how DoD would implement the cyber force model through 
FY 2016, Although the Integrated Master Plan and Schedule primarily focused on 
staffing the CMF, it also recognized other critical aspects of building a force using a 
DOTMLPF-P framework, to include providing the CMF with capabilities to perform 
missions. However, USCYBERCOM did not develop a strategic roadmap for capability 
development. According to the Joint Staff, Command, Control, Communications and 
Computers (Cyber) Division, branch chief, the Integrated Master Plan and Schedule led 
to developing the Cyber Force Concept of Operations and Employment to continue 
addressing major cyberspace activities. 

(U/ /FOUO) USCYBERCOM developed the Cyber Force Concept of Operations and 
Employment to describe fundamental principles and supporting tactics, techniques, and 
procedures to support the CMF in conducting military objectives. Although the Cyber 
Force Concept of Operations and Employment also provided planning guidance and 
described USCYBERCOM’s way forward to build the CMF force model based on elements 
of a DOTMLPF-P framework, the analysis was not comprehensive and did not include 
planning facts, assumptions, and constraints that fully addressed known capability gaps 
that affected the CMF. 
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(U// FOUOj Furthermore, the Services did not develop a DOTMLPF-P framework that 
defined their strategies to build and field CMF teams. ARCYBER, FLTCYBER, AFCYBER, 
and MARFORCYBER officials acknowledged a strategic framework was needed; 
however, they stated that the Service Components were more concerned with staffing 
CMF teams than in establishing a DoD strategy involving full DOTMLPF-P consideration. 

(U/ /rOUO) A MARFORCYBER official stated that the command took initiative to begin 
developing a DOTMLPF-P in 2013 to support its ability to implement the CMF for 
elements within its control; however, MARFORCYBER did not complete the framework 
because the command prioritized building and fielding CMF teams. Additionally, 
AFCYBER created a strategic plan, but did not complete a DOTMLPF-P framework. 18 

(U/ / ' FOOO) The cyber environment continues to rapidly evolve and is unconstrained by 
global boundaries that create unparalleled challenges to traditional military integration, 
synchronization, coordination, and deconfliction processes. These challenges, coupled 
with the tempo of cyberspace operations, require an approach that is more centralized 
and comprehensive to ensure the CMF is provided with needed and timely capabilities 
to perform missions. The lack of a joint USCYBERCOM-Ied DOTMLPF-P framework will 
continue to affect DoD's ability to implement an effective CMF. The Commander, 
USCYBERCOM; Chiefs of Staff for the U.S. Army and U.S. Air Force; the Chief of Naval 
Operations; and the Commandant of the Marine Corps, in coordination with the 
Commanders, ARCYBER, FLTCYBER, AFCYBER, and MARFORCYBER should develop a 
DOTMLPF-P framework to address strategies that build, grow, and sustain the CMF. 

(U) Existing Cyber Capability Development Process Needed Improvement. 

(U/ /rOUO) USCYBERCOM's process defined in USCYBERCOM Instruction 3700-07 19 to 
anticipate joint cyber warfighter requirements and develop solutions to meet these 
requirements was ineffective. The process included using the Integrated Capability 
Requirement Working Group and the CCR to provide situational awareness of DoD's 
offensive cyberspace development efforts. The process described how USCYBERCOM 
would prioritize, invest, and oversee operational requirements and cyberspace 
capabilities funded by the command. Although USCYBERCOM established these 
processes, USCYBERCOM officials stated that they did not have assurance that all 


18 ( c/yncL to ugai rvcv) 


ARMY; NAVY; USAF; USMC: (b)( l),Sec. 1.4(g) 


19 (U) USCYBERCOM Instruction 3700-07, "Cyber Capability Development Policy" February 20, 2014, Section 2.1, "Cyberspace 
Capability Development Process " 
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(U) Finding 


(U// FOHOj Service Component cyber capability development efforts were vetted 
through the Integrated Capabilities Requirements Working Group or included in 
the CCR. 

(U/ / F6 W D 1 ) The Integrated Capabilities Requirements Working Group was established 
to assess capability gaps and synchronize, prioritize, and deconflict capability 
requirements and development. The Integrated Capability Requirements Working 
Group was intended to: 

• (UZ/ POWO) review operational cyberspace requirements provided by the 
JFHQ-Cs for the Service Components, CMFs, combatant commands, and the 
JFHQ-DoDIN; 

• (U/ /FOUOj assist in documenting operational, functional, and technical 
requirements; and 

• (U/ /FQUQ) recommend material and non-material solutions. 

(U//WTO) According to USCYBERCOM, the 
CCR was intended to improve information 
exchange, provide situational awareness of 
existing capabilities to reduce the risk of 
developing duplicative capabilities, and 
identify national offensive and defensive cyber capability gaps. However, the CCR was 
unreliable for providing situational awareness and did not support tool developers, 
operators, and planners because it only included developed capabilities. Specifically, 
officials from the Service Components responsible for capability development did not 
consider the CCR to be reliable because existing capabilities in the CCR did not fully 
describe the function or use of the capability and did not include capabilities under 
development. An extract from March 2015 showed incomplete or missing information 
and did not thoroughly describe the functions of the capabilities. 20 Without including all 
capabilities in the CCR and relevant information about each capability, the CCR was not 
effective and could not support developers and planners as intended. 


(IV/rC'JO) The CCR was unreliable 
for providing situational 
awareness and did not support 
tool developers, operators, and 
planners because it only included 
developed capabilities. 


20 (U) We did not further describe the content of the CCR or identify the number and type of capabilities included in the 
database because the information is classified TOP SECRET. 
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(U] Finding 


(U) Actions Taken Improved the Reliability and Use of the CCR 



(U) Based on USCYBERCOM revisions to the CCR and its direction to include all 
offensive and defensive capabilities in the database, and the Deputy Secretary’s 
required actions to make the CCR more reliable, we did not recommend further 
corrective actions. 


(U) U.S. Cyber Command Lacked Authorities to Lead CMF 
Implementation, Development, and Sustainment 



21 (U) USCYBERCOM Task Order 15-0087, "Directive to Enter or Update Cyber Capabilities into the CCR," Version 2.7, 
May 28, 2015 (U//FOUO). 

22 (U) Deputy Secretary of Defense memorandum, "Follow-on Guidance from the April 18, 2015, Cyber Deep Dive," « 
June 3, 2015 (S//RELTO USA, FVEY). 

23 (U) USCYBERCOM Operational Directive 12-001, April 5, 2012 (S//RELTO USA, FVEY). 

SECRET//NOFORN 


DODIG-2016-026 | 15 















SECRET//NOFORN 


(U) Finding 


yzwm 

sim 




___.5IARMY; NAVY; USAF; USMC: (b)(1). Sec. 1.4(g) 




(U// FOUO) The Commanding General, ARCYBER, and 
the Second Army stated that resources, appropriate 
authorities, organizations, and capabilities, which 
could be synchronized in time and space with a 
singular purpose to accomplish directed missions, 
were needed. 25 In April 2015, USCYBERCOM, the 


(U//rC'JC) Resources, 
appropriate authorities, 
organizations, and capabilities, 
which could he synchronized in 
time and space with a singular 
purpose to accomplish directed 
missions, were needed 


Services, and D1SA completed the "mission alignment board" to finalize proposed 


mission objectives for the remaining CMF teams to be fielded in FY 2015 and FY 2016. 


The outcome of the mission alignment board enabled USCYBERCOM and the Services to 
begin identifying capability gaps and developing capabilities that affected these 
proposed missions. However, USCYBERCOM officials acknowledged that the command 


lacked appropriate acquisition authorities and the ability to direct, when needed, 


Service capability development. 


[U) The proposed National Defense Authorization Act for FY 2016 includes language to 
provide the Commander, USCYBERCOM limited acquisition authority to develop and 
acquire cyberspace-specific capabilities, equipment, and services. Proposed legislation 
recognizes the limitations of the USCYBERCOM Commander to ensure adequate 
capabilities are available to support CMF mission requirements; however, it does not 



ARMY; NAVY; USAF; USMC: (b)(1), Sec. 1.4(g) 


25 (U) Statement by the Commanding General, ARCYBER and Second Army Before the House Armed Services Committee, 
Subcommittee on Emerging Threats and Capabilities, March 4, 2015. 


OECRCT//NOrORN 


noni(, 20i(i-02f>| u> 












SE€RET//NOFCmN 


( LI) Finding 


(U) address other limitations that affect USCYBERCOM's ability to effectively oversee 
and, when needed, direct capability development. 

(U// F € Hfle j) Although the Commander's April 2012 Directive did not further unify 
Service cyber capability development because the Services did not agree with the 
approach, his goal was still valid based on the Services continued approach to 
independently develop capabilities that affected the CMF. The Commander, 
USCYBERCOM; the Chiefs of Staff for the U.S. Army and U.S. Air Force; the Chief of Naval 
Operations; and the Commandant of the Marine Corps should formalize an agreement to 
focus capability development on functional and mission areas consistent with results of 
the mission alignment board. 

(U) DoD Lacked a Unified Defensive Capability 
Development Process 

(U) The Service Components and DISA were independently developing 
Component-specific CPT toolkits 26 based on internal coordination, CPT personnel 
experience, and their individual interpretations of CPT capability needs. As of 
June 2015, the Service Components and DISA were not developing unified defensive 
capabilities. 


(U) Service Component Efforts to Develop 
Defensive Capabilities 



[U/ /FOUO) The Army identified capabilities to include in the deployable toolkit through 
collaboration with a DISA CPT and ARCYBER and U.S. Army Network Enterprise 

26 (U/Z f- ' QUO) A toolkit includes hardware and software that enables CPTs to conduct missions. 
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(U// FOUO) Technology Command interpretations of capabilities needed to perform 



• (U// rOUO) map specific operational environments; 

• (U/ /FOUO) identify and prioritize potential security instances; 

• (U// FOUO) perform hunt missions; and 

• (U/ /F0U0) monitor a network or system. 

(U/ /FOUO) As of March 2015, AFCYBER was modifying and providing additional 
capabilities to the Cyber Vulnerability Assessment-Hunter at an estimated cost of 
$10.7 million to support CPTs. 
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(U) DISA Efforts to Develop Defensive Capabilities 


ARMY; DISA; NAVY; USAF; USMC: (b)( 1), Sec. 1 .4(g) 



27 (U) A rootkit is a collection of files installed on a system to alter the standard functionality of the system in a malicious and 
stealthy way. 
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(U) CPT Capability Baseline Was Needed 


(U// FOUOj The Service Components and DISA independently developed CPT toolkits 
based on their understanding of needed capabilities. This occurred because 
USCYBERCOM did not provide the Components guidance or standard CPT baseline 
requirements and interoperability standards to ensure each CPT could perform core 
defensive capabilities. 
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(U//rOUO) The FLTCYBER JFHQ-C Chief of Staff stated that different Components 
provided CPT support to DISA and the combatant commands. 


DoD OIG: (b)(7)(E) 





(U//E0W0) USCYBERCOM officials stated 
that they planned to use the recommended 
requirements to develop a baseline for all 
CPTs by October 2015. Although 
USCYBERCOM initiated steps to provide a 
CPT baseline, the baseline was not 
approved or developed. 


DoD OIG: (b)(7)(E) 



in coordination with the Service Components and DISA, should develop and specify a 
capability baseline and interoperability standards for CPTs. 
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(U) Finding 


GECRCT//NOPORN 


(U/ /rOUO) CMTs Faced Challenges in 
Performing Missions 


NAVY; USAF; USMC: (b)(1), Sec. 1.4(g) 


• (U) cyberspace intelligence, surveillance, and reconnaissance; 

• (U) operational preparation of the environment; 29 

• (U) defensive cyberspace operations - response actions; 30 and 

• (U) offensive cyberspace operations. 


1ARMY; NAVY; USAF; USMC: (b)( 1), Sec. 1.4(g) 



29 (U) Operational preparation of the environment includes activities in likely or potential areas of operations to prepare and 
shape the operational environment. 


30 (U) Defensive cyberspace operations-response actions are deliberate, authorized defensive measures or activities taken 
outside of the defended network to protect and defend DoD cyberspace capabilities or designated systems. 

31 (U) Section 403-5, title 50, United States Code (2011) authorizes intelligence activities in response to national intelligence 
requirements. 
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(S//REL 70 USA, EVEY ) 



ARMY; NAVY; USAF; USMC: (b)( 1), Sec. 1.4(g) 
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r U) Figure 1. Actions in Red, Blue, and Grey Cyberspace 


Legend: 

DCO-RA Is Defensive Cyberspace Operatlons- 
Response Actions 

ISR Is Intelligence. Surveillance, and 
Reconnaissance 

OPE is Operational Preparation of the Environment 
DCO-IDM Is Defensive Cyberspace Opreations- 
internal Defensive Measures 
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(U) Source: USCYBERCOM Cyber Force Concept of Operations and Employment 


l™™S|ARMY; NAVY; USAF; USMC: (b)( I ), Sec. 1.4(g) 



IARMY; NAVY; STRATCOM; USAF; USMC: (b)(1). Sec. 1.4(g) 


] 


SECRET//NOrORN 


DODIli-2016-026 124 

























SECRET//NOFORN 


(U) Finding 


IESESIARMY; NAVY; USAF; USMC: (b)( I), Sec. 1.4(g) 


IfcffililHARMY; NAVY; USAF; USMC: (b)(1). Sec. 1.4(g) 


(U/ /FOUO) Temporary Army CPT Facilities Provided 
Inadequate Workspace and Network Access 



32 (U) Sections 111, 164, and 167, title 10, United States Code, establish authorities and responsibilities for the Services and 
combatant commands to conduct military operations, including offensive cyberspace operations. 


[ARMY; NAVY; USAF; USMC: (b)(1), Sec. 1.4(e) 



34 (U) USCYBERCOM Cyber Force Concept of Operations and Employment, version 4.1, July 22, 2014 (S//REL TO USA, FVEY). 
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35 (u/ /rouo) 


ARMY: (b)(7)(E) 


36 (U) The Cyber Protection Brigade is subordinate to the 7th Signal Command. 

37 (U) The 513th Military Intelligence Brigade is a subordinate command to the U.S. Army Intelligence and 
Security Command. 
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(U/ /FOUO) 


ARMY: (b)(7)(E) 





(U) See Table 3 on the next page for the locations of ARCYBER temporary CPT facilities 


ARMY: (b)(7)(E) 
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38 (U) Cyber key terrain is any physical or logical elements of a domain that enable mission-essential warfighting functions. 
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(IJ) Finding 


(U// FOUO) Inadequate Capabilities and Facilities 
Jeopardized CMF Mission Success 



The Service Components were responsible for providing adequate facilities 
for non-national CPTs; however, ARCYBER temporary solutions did not provide up to 
HHHHwith adequate workspace and network access to perform missions and 
complete required training. 


ARMY: (b)(7)(E) 



(U) To continue to progress in cyberspace operations, 
DoD needs to close the capability gaps we identified and 
provide CMF teams with appropriate and adequate 
capabilities, facilities, and network access to maintain its 
warfighting advantage. A cyber force, when resourced 
with the appropriate infrastructure, platforms, and tools, 
is the key to dominance in cyberspace. 


(U) To continue to progress in 
cyberspace operations, DoD 
needs to close the capability 
gaps we identified and 
provide CMF teams with 
appropriate and adequate 
capabilities, facilities, and 
network access to maintain 
its warfighting advantage. 
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(U) Management Comments on the Finding and 
Our Response 

(U) Chief of Staff for the U.S. Army Comments 



(U) Our Response 

(U/ /FOUO) We commend the Army for starting the study to identify funding to restore 
and modernize existing facilities. We recognize and did not intend to imply that the 
Army did not use a deliberate decision-making process 

Although we asked on several occasions whether the Army conducted 


ARMY: (b)(7)(E) 


assessments 


ARMY: (b)(7)(E) 


|we were not provided the cost-benefit analysis. 
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(U//rOUO) As previously reported, the Army did not conduct a detailed assessment to 
conclude whether 


ARMY: (b)(7)(E) 


jjhad sufficient SCIF workspace until August 2013. 
Therefore, we did not revise the report based on the additional documentation 
provided by the Army. 


(U) Recommendations, Management Comments, and 
Our Response 

(U) Recommendation 1 

(U) We recommend the Commander, U.S. Cyber Command, and the Chiefs of Staff 
for the U.S. Army and U.S. Air Force, the Chief of Naval Operations, and the 
Commandant of the Marine Corps develop a doctrine, organization, training, 
materiel, leadership and education, personnel, facilities, and policy framework 
that address strategies to build, grow, and sustain the Cyber Mission Force. 


(U) Commander , U.S. Cyber Command Comments 


IfcSSESARMY; USAF; USMC: (b)(1). Sec. 1.4(g) 


(U) Our Response 

(U) Comments from the Commander partially addressed the recommendation. 
Although the Commander agreed with the recommendation to build and mature its 
existing DOTMLPF-P framework, he did not state the specific actions USCYBERCOM 
would take to provide a comprehensive strategy across all elements of the DOTMLPF-P 
framework. Therefore, we request that the Commander, USCYBERCOM, provide 
comments on the final report no later than December 24, 2015. 
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(U) Chief of Naval Operations Comments 


(U//'F0UO) The Director, Warfare Integration, responding for the Chief of Naval 
Operations, jj[ 


AVY: (b)(5) 



(Uj Our Response 

(U) Comments from the Director addressed the recommendation, and no further 
comments are required. 

(U) Chief of Staff for the U.S. Army Comments 

(U/ /FOUO) The Chief, Cyberspace and Information Operations Division, responding for 
the Chief of Staff for the U.S. Army, agreed, stating that the Army was in the process of 
developing a comprehensive cyberspace strategy that presented the Army’s vision to 
have cyberspace operational forces, capabilities, facilities, and partnerships ready and 
able to effectively provide support to regional, global, joint, and Army operations. The 
Chief stated that the strategy would drive investment, workforce, facility, and doctrinal 
changes. Additionally, the Chief stated that the U.S. Army Training and Doctrine 
Command established a Cyber Center of Excellence in January 2014 to serve as the 
Army's lead organization for Force Modernization. Since the Cyber Center of Excellence 
was established, the Chief stated it developed a DOTMLPF-P framework and a strategy 
to build, grow, and sustain soldiers under a new Career Management Field (CMF-17) to 
meet Army CMF requirements. 

(U// FOUO) However, the Chief stated a need also existed for a Joint Services 
assessment across the entire DOTMLPF-P that focused on integrating efforts and 
strategies to further support building, growing, and sustaining the CMF. Specifically, the 

-SE €RET//NOFORN 


| :c( 









S ECRCT//NQFORN 


IU) Finding 


(U// FQ fc i Q ) Chief stated that a Joint Services assessment would allow the Services to 
share independent strategies, identify cross-cutting capabilities, and foster innovative 
approaches. 

(U) Our Response 

(U//rOUO) Comments from the Chief addressed the recommendation, and no further 
comments are required. We agree an overarching, Joint Services DOTMLPF-P 
assessment is needed and would benefit DoD's ability to build, grow, and sustain the 
CMF. Our intent was for USCYBERCOM, as the DoD cyberspace focal point, to lead 
efforts to develop a comprehensive DOTMLPF-P framework based on its assessment 
and the individual assessments and strategies developed by the Service Components. 

(U) Management Comments Required 

(U) The Chief of Staff for the U.S. Air Force and the Commandant of the Marine Corps did 
not respond to the recommendation. The Chief of Staff, AFCYBER, provided comments 
on the draft report; however, Air Force officials stated that comments from the Chief of 
Staff for the U.S. Air Force would be provided only in response to the final report. The 
Commander, MARFORCYBER, also provided comments on the draft report, but 
documentation from Headquarters, Marine Corps clearly stated that the comments 
represented MARFORCYBER’s position. Although we attempted to clarify whether 
MARFORCYBER was responding on behalf of the Commandant, we did not receive a 
further response from the Marine Corps. We request the Chief of Staff for the U.S. Air 
Force and the Commandant of the Marine Corps provide comments on the final report 
no later than December 24, 2015. 

(U) Recommendation 2 

(U) We recommend the Commander, U.S. Cyber Command, and the Chiefs of Staff 
for the U.S. Army and U.S. Air Force, the Chief of Naval Operations, and the 
Commandant of the Marine Corps formalize an agreement to focus capability 
development on functional and mission areas consistent with results of the 
mission alignment board. 

(U) Commander, USCYBERCOM Comments 

(U/ /FOUO) The Commander, USCYBERCOM, agreed, stating that it was important for 
the cyber force to have an integrated approach for capability development. The 
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(U/ Z - PQUO) Commander stated that USCYBERCOM needed to engage with the Office of 
Secretary of Defense and Service Chiefs to coordinate and begin developing formal 
agreements to focus capability development and facilitate integrated development 
approaches. The Commander also stated that limited acquisition authority described in 
the draft FY 2016 National Defense Authorization Act, if received, would support 
increased capability development of functional and mission areas consistent with the 
results of the mission alignment board. 

(U) Our Response 

(U) Comments from the Commander addressed the recommendation, and no further 
comments are required. 


(U) Chief of Naval Operations Comments 



(U) Our Response 

(U) Comments from the Director addressed the recommendation, and no further 
comments are required. 


(U) Chief of Staff for the U.S. Army Comments 

(U/ /FOUO) The Chief, Cyberspace and Information Operations Division, responding for 
the Chief of Staff for the U.S. Army, agreed, stating that a formal memorandum of 
understanding for capability development that focused on the CMF mission alignment 
board for CMTs and CPTs was needed between the Services. The Chief stated that the 
Army's recently established Cyber Acquisition, Requirements, and Resourcing working 
group shaped the Army’s efforts by providing requirements and acquisition support 
needed to rapidly develop and deliver new Army cyberspace capabilities to its force. 


ARMY: (b)(7)(E) 
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(U) Our Response 

(U) Comments from the Chief addressed the recommendation, and no further comments 
are required. 

(U) Management Comments Required 

(U) The Chief of Staff for the U.S. Air Force and the Commandant of the Marine Corps did 
not respond to the recommendation. The Chief of Staff, AFCYBER, provided comments 
on the draft report; however, Air Force officials stated that comments from the Chief of 
Staff for the U.S. Air Force would be provided only in response to the final report. The 
Commander, MARFORCYBER, also provided comments on the draft report, but 
documentation from Headquarters, Marine Corps clearly stated that the comments 
represented MARFORCYBER’s position. Although we attempted to clarify whether 
MARFORCYBER was responding on behalf of the Commandant, we did not receive a 
further response from the Marine Corps. We request the Chief of Staff for the U.S. Air 
Force and the Commandant of the Marine Corps provide comments on the final report 
no later than December 24, 2015. 

(U) Recommendation 3 

(U) We recommend that the Commander, U.S. Cyber Command, in coordination 
with the Service Components and the Defense Information Systems Agency, 
develop and specify a capability baseline and interoperability standards for all 
Cyber Protection Teams. 


(U) Commander , USCYBERCOM Comments 
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ARMY; USAF; USMC: (b)(1). Sec. 1.4(g) 





(U) Our Response 

(U) Comments from the Commander addressed the recommendation, and no further 
comments are required. 


(U) Chief of Naval Operations Comments 



(U) Our Response 


lARMY; USAF; USMC: (b)(1). Sec. 1.4(g) 




(U) Recommendation 4 

(U) We recommend the Commander, Army Cyber Command and Second Army 
develop a time-sensitive plan of action and milestones to provide all Army Cyber 
Protection Teams with adequate workspace [ 


ARMY: (b)(7)(E) 


(U) Commander; U.S. Army Cyber Command and 
Second Army Comments 

(U) The Commander, ARCYBER, agreed, stating that the U.S. Army Network Enterprise 
Technology Command was working with the Cyber Protection Brigade to assist in 
resourcing facilities and network improvements. The Commander stated that ARCYBER 
and the U.S. Army Network Enterprise Technology Command completed a full facility 
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iV; 

(U) and network analysis of capabilities needed and developed a plan of action and 
milestones to provide Army CPTs with adequate workspaceF 


ARMY: (b)(7)(E) 



(U) Our Response 

(U) Comments from the Commander addressed the recommendation, and no further 
comments are required. 


(U) Unsolicited Management Comments and 
Our Response 

(U) Commander, MARFORCYBER Comments 



(U/ / ' FOUO) Additionally, the Commander stated that a formal capability development 
agreement was not needed. Instead, the Commander stated that the issuance of a task 
order, operational order, or fragmentary order would be more appropriate. The 
Commander noted that the mission alignment board process was relevant to only CMTs 
and NMTs, not CPTs. Further, the Commander stated that a capability baseline and 
interoperability standard for CPTs was needed. However, the Commander noted that 
the baseline should not restrict CPTs from adapting their tools and methodologies to 
meet emerging threats. The Commander stated that the baseline should be established 
using functional and mission analysis of CPT operations that considered the current 
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(U/ /FOUO) operating environment as well as the expected future Joint Information 
Environment. The Commander stated that an acceptable tools list with a universal 
authority to operate on the DoDIN, or portions of the DoDIN, was also needed to 
provide CPTs with flexible options to enable them to rapidly implement and respond to 
incidents. 

(U) Our Response 

(U/ /FOUO) We commend MARFORCYBER for developing a strategy to incrementally 
complete a MARFORCYBER-wide DOTMLPF-P framework to build, grow, and sustain 
the CMF and for recently completing its first assessment as part of the strategy. 
MARFORCYBER recognized that the CPT baseline capability should be based on 
functional and mission analysis and be approved to operate on the DoDIN or portions of 
it to increase the CPTs' ability to promptly and effectively perform incident response 
missions. We acknowledge that the CPT capability baseline should not restrict CPTs 
from adapting their tools and methodology to meet emerging threats. 

(U//F©tf0j) We recognize and agree that capability development to support the CMF 
should be a joint effort. We understand other types of written direction could meet our 
intent. However, as stated in this report, similar efforts by the Commander, 
USCYBERCOM, to specifically direct capability development efforts in Operational 
Directive 12-001 were not successful because agreement between the Services and 
USCYBERCOM had not been reached. As the Services and DoD continue to develop a 
broad range of cyberspace tools and capabilities, an agreement and collaboration 
among the Services and USCYBERCOM to align multiple capability development efforts 
and reduce potential redundancy while meeting combatant command and Service 
requirements is needed. The lack of broader agreement to synchronize and leverage 
Service-led capability development efforts could result in developing redundant 
capabilities and, therefore, not using limited resources efficiently. 

(U) AFCYBER and 24th Air Force Comments 

(U/ /FOUO) Although not required to comment, the Chief of Staff, AFCYBER, stated that 
AFCYBER would continue to work with Headquarters, U.S. Air Force and USCYBERCOM 
to develop or update a DOTMLPF-P framework. The Chief of Staff stated that AFCYBER 
would also continue to document capability requirements and associated capability 
gaps to build the current force, grow and mature the full CMF, and develop and sustain 
CMF capabilities. However, the Chief of Staff stated that an Air Force Space Command 
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(U// rOUO) Project Task Force already made progress towards institutionalizing a 
DOTMLPF-P framework and developed a strategic level doctrinal framework in the CMF 
Program Action Directive, January 15, 2014. 


(U//' F Q 446 ' ] The Chief of Staff stated that the CMF Program Action Directive established 
DOTMLPF-P guidance that included planning actions focused on training, budget, 
facilities, equipment, and personnel across the total force for the Air Force CMF build. 
The Chief of Staff stated that the framework supported the Air Force in building 


IDoDOIG: (b)(7)(E) 
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The Chief of Staff also stated that the current strategic guidance enabled 
AFCYBER to successfully field, train, organize, equip, and develop capabilities to meet 
Air Force CMF needs across the entire Air Force presentation of forces. 


(U/ /F Q U ' O i ) Additionally, the Chief of Staff stated AFCYBER would continue to work with 
Headquarters, U.S. Air Force, USCYBERCOM, and other CMF oversight organizations, in 
accordance with the Cyber Force Concept of Operations and Employment, to formalize 
agreements that allow combatant commanders to direct capability development that 
supports their mission requirements and priorities. 


(U) Our Response 

(U) We commend AFCYBER for developing a strategic roadmap to build, grow, and 
sustain the CMF. We recognize the Air Force Space Command strategy provides the 
foundation for AFCYBER to develop and update its DOTMLPF-P framework. 
Additionally, we commend AFCYBER for acknowledging the need existed to formalize 
agreements to develop capabilities that support Service and combatant commander 
mission requirements and priorities. 
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(U) Appendixes 


(U) Appendix 


(U) Scope and Methodology 


(U) We conducted this performance audit from November 2014 through September 
2015 in accordance with Generally Accepted Government Auditing Standards. Those 
standards require that we plan and perform the audit to obtain sufficient, appropriate 
evidence to provide a reasonable basis for our findings and conclusions based on our 
audit objectives. We believe that the evidence obtained provides a reasonable basis for 
our findings and conclusions based on our audit objectives. 

(U) We visited Headquarters, USCYBERCOM, and Headquarters, NSA, Fort Meade, 
Maryland. Specifically, we interviewed officials from the USCYBERCOM Operations 
Directorate (J3), Logistics Directorate (J4), Capability and Resource Integration 
Directorate (J8), and Advanced Concepts and Technology Directorate (J9) to determine 
their processes for identifying requirements, developing implementation plans and 
strategies to locate CMF teams in appropriate workspaces with access to needed 
networks, and planning and funding facilities, equipment, and capabilities to support 
CMF teams. 

(U// FOUO) We also interviewed USCYBERCOM officials to determine processes for 
coordinating and facilitating capability development across the Service Components. 
Additionally, we met with the Commander, Cyber National Mission Force, to discuss his 
vision for pooling CMF tool developers, assigning CMF missions and targets, and 
standardizing CPT requirements and capabilities. Further, we attended th e ||||jH 



ll^l^^^excrcisc to observe the types of capabilities a NMT and national CPT used 

or had access to for performing missions. 



(U//P0W©) 



(U/ / ' F9U0) We reviewed three task and two fragmentary orders issued by 
USCYBERCOM and the implementation plan for fielding the CMF teams; standard 
equipment configurations based on CMF team work roles to identify desktop equipment 
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(U) Appendixes 



(U// FOUO) We visited Headquarters, ARCYBER, Fort Meade, Maryland; Headquarters, 
FLTCYBER, Fort Meade, Maryland; Headquarters, AFCYBER, Joint Base San 
Antonio-Lackland, Texas; and Headquarters, MARFORCYBER, Columbia, Maryland. We 
interviewed officials from ARCYBER, FLTCYBER, AFCYBER, and MARFORCYBER 
responsible for staffing, equipping, assessing locations and providing facilities, and 
identifying capability gaps and developing capabilities to support Service-fielded CMF 
teams. Additionally, we interviewed officials from ARCYBER, FLTCYBER, AFCYBER, and 
MARFORCYBER to identify responsibilities for providing administrative and operational 
control of the CMF. We reviewed agreements to identify facilities and responsibilities 
for locating Army, Navy, and Marine Corps CMF teams; ARCYBER, AFCYBER, and 
FLTCYBER assessments to identify processes and criteria for locating CMF teams; plans 
for locating CMF teams to identify temporary and permanent CPT facilities; initial and 
full operational capability designations to identify the missions of CMF teams; and 
operational needs, capability gaps, and CPT flyaway kit configurations to identify 
offensive and defensive capabilities used or needed by CMTs and CPTs. 

(U) In addition, we interviewed officials from Joint Staff Operations Directorate (J3), 
Command, Control, Communications and Computer Directorate (J6J, Joint Force 
Development Directorate (J7), and Force Structure, Resource and Assessment 
Directorate (J8) to determine oversight responsibilities for implementing the CMF build 
and to identify their involvement in identifying CMF facility, equipment, and capability 
requirements. We also interviewed officials from the U.S. Pacific Command and 
U.S. European Command joint cyber centers responsible for developing missions and 
targets, integrating cyberspace into command plans and operations, and coordinating 
facility and capability gaps with their respective JFHQ-Cs. We reviewed integrated 
priority lists identifying cyberspace priorities and capability gaps; mission and target 
assignments for CMTs; and unfunded CPT facility requirements. 
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(IJ) Appendixes 


NSA: (b)(3), 10 USC § 3605 


Component-designated facilities; and Headquarters, DISA, Fort Meade, Maryland. We 
interviewed CMF team leads, deputy team leads, and non-commissioned officers in 
charge responsible for assessing equipment and capability needs and planning, 
implementing, and leading team missions to review the adequacy of their facilities, 
equipment, and capabilities. See Table A.l for the Service Component that fielded the 
teams, the specific CMF team visited, and the location of each team. 


(S//RCL TO USA, rVCY) Table A. j 


/ /r»i-i Ti-i • ir * ri »rw» 
-*! / m-L. • v w jn ( i vli| 


ARMY; NAVY; USAF; USMC: (b) 
(D.Scc, 14(g) 


ARMY; NAVY; USAF; USMC: (b)( 1), Sec. 1.4(g) 


(S #nELTO USA, rvcv ) 

(U) We also reviewed USCYBERCOM, NSA Central Security Service, U.S. Pacific 
Command, and U.S. European Command security classification guides to appropriately 
classify information and portion mark the report. 

(U) Use of Computer-Processed Data 

(U) We did not use computer-processed data to perform this audit. 
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jU) Appendixes 


(U) Prior Coverage 

(U) During the last 5 years, the GAO and the Department of Defense Inspector General 
(DoD IG) issued six reports discussing DoD's ability to resource and conduct cyberspace 
operations. Unrestricted GAO reports can be accessed over the Internet at 
http://www.gao.gov . 


(U) GAO 



(U) Report No. GAO-11-75, "Defense Department Cyber Efforts: DoD Faces Challenges 
in its Cyber Activities,” July 25, 2011 

(UJ Report No. GAO-11-421, "Defense Department Cyber Efforts: More Detailed 
Guidance Needed to Ensure Military Services Develop Appropriate Cyberspace 
Capabilities," May 20, 2011 


ARMY; USAF; USMC: (b)(1). Sec. 1.4(g) 


(U) DoD OIG 

(U) Report No. DODIG-2015-117, "USCYBERCOM and Military Services Need to Reassess 
Processes for Fielding CMF Teams,” April 30, 2015 (S//NF) 


DoD OIG (b)(7)(E) 


(U//Fe«ej) Report No. DODIG-2015-048, "Joint Cyber Centers|j_ 

| Cyberspace Operations," 

December 8,2014 (S//NF) 
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(U) Management Comments 


(U) Management Comments 

(U) U.S. Cyber Command 


■se orccTworoRH 

DEPARTMENT OF DEFENSE 
UNITED STATE8 CYBER COMMAND 

9800 SAVAGE ROAD. SUITE 01M 
FORT GEORGE G MEADE, MARYLAND 20755 


OCT 1 4 2015 

Reply to: 

Commander 

MEMORANDUM FOR THE INSPECTOR GENERAL, DEPARTMENT OF DEFENSE 
Through: DIRECTOR OF THE JOINT STAFF 

SUBJECT: (U//FOWO) Response to report: Combat Mission Teams and Cyber Protection 
Teams Lacked Adequate Capabilities and Facilities to Perform Missions (Report 
No. DODIG-2015-0059) 

1. (IJ) United States Cyber Command (USCYBERCOM) appreciates the opportunity to respond 
to the subject DoDIG report and provides the following response to recommendations one, two, 
and three. 

2. (U) Recommendation One. The DoDIG report recommends that Chiefs of Staff for the, U.S. 
Army and U.S Air Force; Chief of Naval Operations; the Commandant of the Marine Corps; and 
the Commander, U.S. Cyber Command develop or update a doctrine, organization, training, 
materiel, leadership and education, personnel, facilities, and policy (DOTMLPF-P) framework to 
document capability requirements and associated capability gaps to build the current force, grow 
and mature the full Cyber Mission Force (CMF), and develop and sustain CMF capabilities. 


"■K!J!!5|ARMY; USAF; USMC: (b)(1). Sec. 1.4(g) 
p\RMY; USAF; USMC: (b)( I), Sec. 1.4(g) 


* 1^^Bl ARMY; USAF; USMC: (b)( I). Sec. I.4(t>) 
IARMY; USAF; USMC: (b)( I), Sec. 1.4(g) 
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(II) Management Comments 


(U) U.S. Cyber Command (cont'd) 


■ Q ge i H flWMORQH* 


3. (U//HW8) Recommendation Two. The Commander, USCYBF.RCOM; Chiefs of Staff for 
the U.S. Army and U.S. Air Force; the Chief of Naval Operations; and the Commandant of the 
Marine Corps should formalize an agreement to focus capability development on Junctional and 
mission areas consistent with the results of the mission alignment board. 

(U/^J'OUO) USCYBERCOM agrees with Recommendation Two. It is important for the cyber 
force to have an integrated approach for capability development; USCYBERCOM would need to 
engage with OSD and Service Chiefs to coordinate and begin developing formal agreements to 
focus capability development and facilitate integrated development approaches. Limited 
acquisition authority as described in the draft FY16 National Defense Authorization Act, if 
received, would also support increased coordination of capability development on Junctional and 
mission areas consistent with the results of the mission alignment board. 

4. (U/ /POTO) Recommendation Three. The Commander, USCYBERCOM, in coordination 
with the Service Components and D1SA, should develop and specify a capability baseline and 
interoperability standards for Cyber Protection Teams (CPTs). 







MICHAEL S. ROGERS 
Admiral, U.S. Navy 


Commander 


Copy to: 

Commander, USSTRATCOM 
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(U) Management Comments 


(U) Chief of Naval Operations 



UNCLASSIITKI) UPON Kl'MOVAl. OF EWLOSUK! il) 


DEPARTMENT UF THE NAVY 


Omk* IK tin Ct tr O'ltlvM (Il t* 11151 V 

x*9N*vrr>wr*«QM 
iv»-tM u*i nc x v^V5c*>i 


1210 

ScrN2NftFJ/S5SU9(X»2 
October JO, 2015 



Readiness and Cyber Operation* 
4800 Mark Center Drive 
Alexandria. VA 22350-1500 


Dour 



(I i/ ^#**1 Enclosure (I) is die Na\ y icsporisc m lhe Department ol Defense Inspector 


(iencrul drull audit report on the subject of “Combai Mission I earn-* and Cyber Protection l eone 
Licked Adequate Capabilities and Facilities to Perforin Missions" (Project No DJ0I5 D000|<( 
0059.000) dated 17 September 2015 

id) flic Navy appreciates theoppoiiumiy lo respond to Hierlr.ili report Ms |Himl ol 





Sincerely. 



Nancy Norton 

Rear Admiral, l S N.i\> 

Director. Warfare integration 


Enclosure I NJ/NfiF Responses lo DODIU Recommendations Ptoiwl No. D20I5IXJOOKt 
0059.000)01* 17 Sep 15 


Derived from Multiple Sources 
Declassify on ^ 




1 N( I.ASSII II IMIPON REMOVAL Ol* KNC LOSURi; 11) 
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(U) Management Comments 


(U) Chief of Naval Operations (cont'd) 




DEPARTMENT OF THE NAVY 

Ofict o» im tom or N ArM. OrciutT3Nt 
9000 tUv* Pi hi 
WAUfMOtON, DC 20J5O KKJO 


1210 

Ser N2N6F.VS5SI I‘XX,;? 
October 30. 2015 


ITom. Director, Warfare Integration (OPNAV N2/N6F) 

T o Deputy Assistant Inspector General Readiness ;md Cyber Operations 

Subj; (II NAVY RESPONSE TO DODIG RECOMMENDATIONS PROJECT NO 

D20I5 D000RC (KI59.(XJ0) DATED 17 SEPTEMBER 2015 

Reference (a) DODIG Draft Audit Report of 17 Sep 15 

(It) (U) Nasal lns|tccloi General Audit Liaison Manual ft 05U 
(c) (U) Dcpartnicnl of Delcnsc INSTRUCTION 7650.03 

l 1 1 .ttatam In response to reference (a) and in accordance with references (h) and (cl. the 
following input is provided to subject report: 

• <1 1 ) Kccommcndnthm I 


(U)Wc recommend (he Chiefs of Stuff forihcll.S Army and IT S Air Force: the Chief ol 
Naval Operations; the Commandant of the Marine Corps; and the Commander 11 S Cyber 
Command develop a Doctrine. Organization, Training. Material. Lcadciship and Education, 
Personnel, Facilities and Policy (DOT MI.P-I J framework that addresses strategics to build grow and 
sustain the Cyber Mission Force. 



• <1 ’ *.H yviMi;y i Jv n <»atli»n 2 

(U) We recommend the Commander. U.S. Cyber Command, and the Chiefs of Staff for the 
I J.S Army and I J.S. Air Force, the Chiel of Naval Operations and the Commandant of tin.* Marine 
Corps formalize an agreement to focus capability development on functional and mission areas 
consistent with the results ol mission alignment board 


Derived from. IJSCCI5200-07 
Declassify on 
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(U) Management Comments 


(U) Chief of Naval Operations (cont'd) 


IARMY: NAVY; USAF; USMC: (b)(1). Sec. 1.4(g) 




• (1 1 > Uccotmiundnllon 3 


< l ‘ j We recommend I he (’ommamlci. I I.S. C’ylx/r Command. in comdinatinn with Ihc 
Service Components and Ihc Defense Information Systems Agency, develop and specify a 
capability baseline and interoperability standards for all Cyber Protection Teams iCPH 


ARMY; NAVY; USAF; USMC; (b)( I), Sec. 1.4(g) 


1 titflnfevi 

N A NORTON 
Rcui Admiral. U.S Navy 
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(U) Management Comments 


(U) U.S. Army Chief of Staff 



DEPARTMENT OF THE ARMY 

OFFICE OF THE DEPUTY CHIEF OF STAFF. G-3/5/7 
3200 ARMY PENTAGON 
WASHINGTON. DC 20310-3200 


DAMO-ODCI 


16 October 2015 


MEMORANDUM FO R Depart ment of D efense (DoD) Inspector General (IG), ATTN: 

Readiness and Cyber Operations. 4800 Mark 
Center Drive. Alexandria. Virginia 22350-1500 


SUBJECT: (U// r OH») Army Comments to DoDIG Draft Report: 1U//FOUO) Combat 
Mission Teams and Cyber Protection Teams (CPTs) Lacked Adequate Capabilities and 
Facilities to Perform Missions’* (D2016-D000RC-0059.000) dated 17 September 2015 
(S//NOFORN) 


1. General Comments: 




1 CJCS Memorandum. 5 December 2012. subject: 30 Nov JCS Tank on CYBERCOM Mission Manpower 
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(U) Management Comments 


(U) U.S. Army Chief of Staff (cont'd) 


nr t i nt 


(ARMY; USAF; USMC: (b)( 1), Sec. 1.4(g) 


2. DODIG Recommendations: 

a. (U) Recommendation 1: We recommend the Chiefs of Staff for the U.S. Army 
and U.S. Air Force; the Chief of Naval Operations; the Commandant of the 
Marine Corps; and the Commander, U.S. Cyber Command develop a doctrine, 
organization, training, materiel, leadership and education, personnel, 
facilities, and policy (DOTMLPF-P) framework that address strategies to 
build, grow, and sustain the Cyber Mission Force. 

b. (U//P OUQ ) Army Response: Concur. There is a need to conduct a 
collaborative Joint Services assessment across the entire DOTMLPF-P that 
focuses on integrating efforts and strategies to support building, growing, and 
sustaining the Cyber Mission Force (CMF). This approach would allow Services 
to share their independent assessments, help determine cross-cutting 
capabilities and foster innovative approaches. The Army is developing a 
comprehensive Cyberspace Strategy that presents the Army vision for 
cyberspace, end states, and major objectives to integrate all Army activities and 
operations in cyberspace and the Information environment. This strategy 
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(U) Management Comments 


seeftCT/ ' /NoroiiN 


(U) U.S. Army Chief of Staff (cont'd) 


fl iiunimmr 



(U) Recommendation 2: We recommend the Commander, U.S. Cyber 
Command, and the Chiefs of Staff for the U.S. Army and U.S. Air Force, the 
Chief of Naval Operations, and the Commandant of the Marine Corps formalize 
an agreement to focus capability development on functional and mission 
areas consistent with results of the mission alignment board. 


d. (U// rQUO) Army Response: Concur. The Army requires a proactive 

governance and management con str_uct^t o ja pi_d ly_ ^Jive^cy bercapabilities with 
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(U) Managemenl Comments 


(U) U.S. Army Chief of Staff (cont'd) 


IARMY: (b)(7)(E) 


u 

DoD OK 


e Headquarters. Department of the Army. ODCI G-39. point of contact is U 



COL, GS 

Chief, Cyberspace and Information Operations 
Division 
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(U) Management Comments 


(U) U.S. Army Cyber Command and Second Army 


uNCLAssiFiED/ /r e n o i tio i al uoe oiiu 

DEPARTMENT OF THE ARMY 
U.8. ARMY CYBER COMMAND AND SECOND ARMY 
8825 BEULAH STREET 
FORT BELVOIR, VIRGINIA 22060-5248 


I 6 OCT 2015 


MEMORANDU M FOR Department of D efense fDoDI InsDector General fIGT ATTN: ItiliUUU 
rrrn hiiiii—^— Readiness and Cyber Operations, 4800 Mark 
Center Drive, Alexandria. Virginia 22350-1500 

SUBJECT: (U ! &&&) Command Comments to DoDIG Draft Report: ■‘(U//FOUO) Combat 
Mission Teams and Cyber Protection Teams Lacked Adequate Capabilities and Facilities to 
Perform Missions" (D2015-DOOORC-0059.000) dated 17 September 2015 (S//NOFORN) 


1. (U) U.S. Army Cyber Command (ARCYBER) reviewed the subject draft report and your 
recommendation: “(U) RECOMMENDATION 4: (U) We recommend the Commander 
Army Cyber Command and Second Army develop a time-sensitive plan of action and 
milestones to provide all Army Cyber Protection Teams with adequate workspace and 


lARMY: (b)(7)(E) 


2. (U) We concur. The Network Enterprise Technology Command (NETCOM) staff are 
currently working with the Cyber Protection Brigade (CPB) to assist in resourcing facilities 
and network improvements. During the course of the audit, ARCYBER and NETCOM 
completed the full facility and network analysis on capabilities needed for the CPB and 
developed a plan of action and milestones to provide all Army Cyber Protection Teams 



GLJCCJU. 

EDWARD C. CARDON 
Lieutenant General, USA 
Commanding 
CF: 

HQ DA (DAMO-ODCI) 

HQ DA (SAAG-ACFO) 

UNCLASSIFIED/ ^* QPr i O I AL U0C OHL¥ 
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(U) Management Comments 


(U) U.S. Marine Corps Forces Cyber Command 


UNCLASSIFIED// ron Orr i OAL UOC OML 1 

UNITED STATES MARINE CORPS 

U. S. KARINS CORPS IX>RCKS CYBERSPACE COHHAMD 
9800 9AVAGE ROAD SUIIE 6850 
PORT MEADE HART I AMD 20755 


iuoo 

CUR 

OCT 20 2015 

From: Commander, U.S. Marine Corps Forces Cyberspace Conm.ind iMARFORCYBERJ 
To: Inspector General, U.S. Uepatttr.cnt of Defense 

Via: Director, Marine Corps Staff 

Sub 3 : DRAFT L'ODIG REPORT D201 b-f>aO3RC-O0b9.000 "COMBAT MISSION 

TEAMS AND CYBER PROTECTION tCAMS LACKED ADEQUATE CAPABILITES AND 
FACILITIES TO PERFORM MISSIONS," DATED SEPTEMBER IV, 201b 
(SECRE17/N0F0RN) 

Enci i 11} (U) MARFORCYBER RESPONSES TO RECOMMENDATIONS (S//REL) 

(2! (U) MARFORCYflF.R SECURITY MARKING REVIEW (S//REL) 

1. (U) PURPOSE. To transmit the approved MARFORCYBER comments pertaining Lo 
the Draft DoDlG report D201b-UUO'JRC-0059.000 “Combat Mission teams and Cynei 
Protection Teams Lacked Adoqunto Capabilities and Facilities to Pei lor in 
Missions." 

2. (U//P**»> BACKGROUND . The Office ol the Inspector General, Department of 
Detense, provided dtaft report D2015-UOOOHC-UOb9.1101), "Combat Mission learns 
and Cyber Protection Teams Lacked Adequate Capabilities and Facilities to 
Perform Missions" dated September 17, 2015 to MARFORCYBER lor review and 
comment. Instructions ire for MARFORCYBER to provide comments on whether 
leadership agrees (concurs) or disagrees {non-concurs) with the findings and 
recommendations in the report. MARFORCYBER was instructed to specifically 
answer reconmendations one, two, and if desired three. Additionally, the 
command has been directed to review all classification markings of the repurt 
and our response. 

3. |U) DISCUSSION 

a. |U) Recoa mendati on 1 . MARFORCYBER concurs; see enclosure (1). 

b. <u> Recommendation 2 . MARFORCYBER non-concurs; see enclosure (1). 

c. (U> Recommendation i . MARFORCYBER concurs; see enclosure (1). 


d. (U) Security Marking Review . Completed; see enclosure (2). 



UNCLASSiPiED// rQ H om e *t uo e c mw 
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( D ) Management Comments 


(U) U.S. Marine Corps Forces Cyber Command (cont'd) 


DORIC DRAFT AUDIT RETORT DATED SEPTEMBER 17, 2015 
PROJECT NO. D20I5-DOOORC 0059.000 

"COMBAT MISSION TEAMS AND CYBER PROTECTION TEAMS LACKED 
ADEQUATE CAPABILITIES AND FACILITIES TO PERFORM MISSIONS” 

U.S. MARINE CORPS COMMENTS TO THE DORIC RECOMMENDATIONS 

RECOMMENDATION I ; DODKi recommends (hat the Chiefs of Stuff for the U.S. Army and 
U.S. Air Force; the Chief of Naval Operations: the Commandant of the Marine Corps: and the 
Commander, U.S. Cyber Command develop u doctrine, organization, (ruining, materiel, 
leadership and education, personnel, facilities, and policy framework that address strategics to 
build, grow, and sustain the Cyber Mission Force. 


COMMANDANT OF THE MARINE CORPS RESPONSE: 



RECOMMENDATION 2 : DODIO recommends that the Chiefs of Stall'for the U.S. Army and 
U.S. Air Force; the Chief of Naval Operations; the Commandant of the Marine Corps; and the 
Commander. U.S. Cyber Command formalize nn agreement to focus capability development on 
functional and mission ureas consistent w ith results of the mission alignment board 

c <)^LLN± )ANT OF HIE MARINE COlj L S Wfl lQMSE: 

(U/VI’fHffy) Non-coneur. I he ability to focus capability development is a joint objective and 
should be led by the Combatant Commander, l ISSTRAI’COM or a delegated representative (e.g. 
USCYBERCOM). No formalized agreement is required; the appropriate mechanism would he 
the issuance of an order (i.e. TASKORD. I’RACJO, OPORD). Iltc Mission Alignment Board 
(MAB) process is only relevant to Combat Mission l oams and National Mission Teams and does 
not provide appropriate criteria for capability development of the Cyber Protection Force (CPF). 


mmamm 

ci.iiiHctt it) HUNK 

Derived from nsa CS5M I 52 
Dated 200701IIK 
IktUnWy On 20461011 

ENCLOSURE (|) 
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(^U) Management Comments 


(U) U.S. Marine Corps Forces Cyber Command (cont'd) 


RECOMMENDATION 3 : DODIO recommends that Commander. ll.S. Cyber Command, in 
coordination with the Service Components and the Defense Information Systems Agency , 
develop and specify a capability baseline and interoperability standards lor all Cyber Protection 
Teams. 

COMMANDANT OK THE MARINE COUPS RESPONSE ; 

(U/ fl"t)UO ) c oncur. MARFORCYBER agrees that there should he u capability baseline and 
interoperability standard for the CPE. I he standard should consider today’s operating 
environment and the future Joint Information Environment (JIE) and should he codified in the 
Cyber Force Concept of Employment (CFCOK) or other directive documents. I he standard 
should Ik established using a functional and mission analysis of CP I operations. It should 
specify u minimum capability, hut not limit CPTs from exceeding the standard when necessary 
and where possible, (liven the evolutionary nature of the operating environment, the baseline 
standard must not restrict CPTs from adapting their tools and methodology to meet emerging 
threats. I recommend the baseline identify functions or capabilities rather than specific tuols. 
Finally, the creation of an acceptable tools list with a universal authority to operate (ATO) on 
any DoDIN network, or porlion thereof, would provide teams flexible options, enabling rapid 
implementation and increasing operational tempo lor incident response forces. 


ENCLOSURE (l ) 
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(U) Management Comments 


(U) U.S. Air Forces Cyber Command and 24th Air Force 



UNCLASSIFIED/ U6E 0 # i¥ 
DEPARTMENT OF THE AIR FORCE 

HJADQUARIERS 24IH AIR TORCE (AIR EORCESCVBERmAFSPO 
JOINT BASE SAN ANTONIO LACKLAND TFXAS 


19 October 2015 


MEMORANDUM FOR Office of the Inspector General Department of Defense 

FROM: 24AF/CC 

.1515 S. General McMullen Drive 

Joint Base San Antonio - I.Hckland TX 78226-9853 

SUBJECT: Draft Report for Project No. D2OI5-DOOORC-0O59.OO0 

1. (UW9W*) PURPOSE. Obtain 24 AF/CC coordination and approval of 24 AF comments pertaining to 
the Draft Report for Project No. D2015-D000RC-0059.0O0 

2. (UA I P OUO ) BACKGROUND. The Office of the Inspector General Department of Defense, issued the 
draft report for Project No. D2OI5-D000RC-0ftS9.0OO, "Combat Mission Tennis and Cyber Protection 
Teams Lacked Adequate Capabilities and Facilities to Perform Missions" dated September 17.2015 for 
24 AF review and comment. Instructions ore for 24 AF to provide comments on whether management 
agrees or disagrees with the finding nnd recommendations in the report. If in agreement 24 AF is 
instructed to describe what actions have been token or planned to accomplish the recommendations 
including the completion dales. If in disagreement, 24 AF is instructed to give specific reasons for 
disagreement and propose alternative action if appropriate. 

3. DISCUSSION. 24 AF concurs with comments. 

a. (U) DoD IG Recommendation 1 

(U) Wo recommend the Chiefs of Staff for the U.S. Army and U.S. Air Force; the Chief of 
Naval Operations; ihc Commandant of Ihe Marine Corps; and the Commander, 

U.S. Cyber Command develop a doctrine, organization, training, materiel, leadership und 
education, personnel, facilities, and policy framework that address strategics to build, 
grow, and sustain the Cyber Mission Force. 

(U) 24 AF/AFCYBF.R response: 

(U/ /HHJU) lire 24 AF/AFCYBER will continue to work with HQ USAF. and USCYBERCOM 
to develop or update a DOTM1.PF&P framework. The organizations will continue to document 
capability requirements and associated capability gaps to build the current force, grow and mature 
Ihe full CMF, and develop and sustain CMF capabilities. Hie AFSPC Project Task Force 
(PROTAF) has already made progress towards institutionalizing the DOTMLPF framework and 
has produced strategic level doctrinal framework including: 

• (U//WW**) The CMF Program Action Directive (PAD), dated 15 Jan 20M, established 
DOTMLPF guidance for the AF CMF build. The PAD established planning actions across 
training, budget, facilities, equipment, personnel and total force (Air Force Reserves (AFR) 
and Air National Guard (ANG)) lines of effort. The execution arm of our DOTMLPF effort 
and PAD guidance is Ihc Project Task Force (PROTAF) which consists of membership from 
AFCYBER, AFCYBER_F\VD. Air Force Space Command, Headquarters Air Force (IIAF), 
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(Uj Management Comments 


(U) U.S. Air Forces Cyber Command and 
24th Air Force (cont'd) 


UNCLASSIFIED/ 



Date of Completion: Multiple, ongoing actions until full FOC build, 
b. (U) DoD IG Recommendation 2 

(U) We recommend the Commander, U.S. Cyber Command, and the Chiefs of Staff for the 
U.S. Army and U.S. Air Force, the Chief of Naval Operations, and the Commandant of the 
Marine Corps formalize on agreement to focus capability development on functional 
and mission areas consistent with results of the mission alignment board. 

(U) 24 AF/AFCYRER response: 

(U//i (*UU) The 24 AF/AFCYBEK will continue to work with HQ USAF, USCYBLK.COM and 
other CMF oversight bodies such as the CMF rDT Technical Oversight Council, in accordance 
with the Cyber Force Concept of Lmploymcnl (CFCOL) directive, to formalize agreements that 
allow Combatant Commanders, guided by the Mission Alignment Bonrd. to direct capability 
development that support the Combatant Commander’s mission requirements and priorities. 

(U) Date of Completion: On-going activity 

4. (U) VIEWS OF OTHERS. 

NA 
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(II) Management Comments 


(U) U.S. Air Forces Cyber Command and 
24th Air Force (cont'd) 


UNCLASSIFIED/ 


: O W l ¥ 


5. (U) RECOMMENDATION. AFC’YBER concurs with comments to Draft Report for Project No. 
D20I5-D00ORC-0O59.O00 (Tab I). 




Stephen T. Ling, Colonel, USA 
Cine! of Staff 




I Tabs 

Tab 1 - DoDIG Draft Report lor Project No. D2015-D000RC-0059.00O 


GCCRET//NOFORN 


DODIO-2016-026 160 













S E€R - ET//NOFORN 


IU) Source of Classified Information 


(U) Source of Classified Information 


Sourcel: (U) Deputy Secretary of Defense Memorandum, "Resource Management 
Decisions for FY 2014 Budget Request:" S//NF 
Declassification Date: April 10, 2038 
Generated Date: April 10, 2013 

Source 2: (U) USCYBERCOM Cyber Force Concept of Operations and Employment, 
Version 4.1: S//REL TO USA, FVEY 

Declassification Date: August 1, 2039 
Generated Date: July 22, 2014 

Source 3: (U//F OfeK ? )) USCYBERCOM Task Order 13-0244, "Establishment and 
Presentation of CMF Teams in FY 2013:” S//REL TO USA, FVEY 
Declassification Date: March 6, 2038 
Generated Date: March 6, 2013 

Source 4: ( S//REL TO USA, FVE¥ j| 


ARMY; USAF; USMC: (b)(1), Sec. 1.4(g) 


Declassification Date: October 11, 2038 
Generated Date: October 11, 2013 

Source 5: (S//REL TO USA, FVEY) 


ARMY; USAF; USMC: (b)(1). Sec. 1.4(g) 


Declassification Date: May 13,2038 
Generated Date: May 13, 2013 
Source 6: (0//RCL TO USA, TVCY) 

Declassification Date: April 5, 2037 
Generated Date: April 5, 2012 
Source 7: ( 6 #NF - ) 


ARMY; USAF; USMC: (b)(1). Sec. 1.4(g) 


ARMY; USAF; USMC: (b)(1). Sec. 1.4(g) 


Declassification Date: May 19, 2038 
Generated Date: May 19, 2013 

Source 8: (S//REL TO USA ; FVEY) 


ARMY; USAF; USMC: (b)(1). Sec. 1.4(g) 


Declassification Date: June 30, 2038 
Generated Date: March 30, 2015 
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(U) Source of Classified Information 


Source 9: (C//REL TO - tfSA r F¥ B¥) 


ARMY; USAF; USMC: (b)(1), Sec. 1.4(g) 


ARMY; USAF; USMC; (b)(1), Sec. 1.4(g) 


Declassification Date: August 1, 2039 
Generated Date: August 14, 2014 
Source 10:£ S y VW jj 

Declassification Date: November 1, 2039 
Generated Date: November 20, 2014 

Source 11: (U) Deputy Secretary of Defense Memorandum, "Resource Management 
Decisions for FY 2016 Budget Request:" S//NF 

Declassification Date: December 10, 2039 
Generated Date: December 10, 2014 

Source 12 : ( # / t ^ 4 F - ) 1 


ARMY; USAF; USMC: (b)(1). Sec. 1.4(g) 


Declassification Date: June 25, 2040 
Generated Date: June 25, 2015 

Source 13: (S//REL TO USA, FVEY) 


ARMY; USAF; USMC: (b)(1). Sec. 1.4(g) 


Declassification Date: July 19, 2038 
Generated Date: May 1, 2014 

Source 14: (S/ - /MF) | 


ARMY; USAF; USMC: (b)(1), Sec. 1.4(g) 


Declassification Date: August 1, 2039 

Generated Date: October 22, 2012 (updated November 20, 2012) 

Source 15: (S//REL TO USA, FVEY) ! 


ARMY; USAF; USMC: (b)(1). Sec. 1.4(g) 


Declassification Date: December 19, 2039 
Generated Date: January 9, 2015 

Source 16: (U) Request for Initial Operational Capability Designation 
S//RELTO USA, FVEY 

Declassification Date: September 13, 2038 
Generated Date: September 13, 2013 
Source 17: (U) 400 CMT Initial Operational Capability Designation: 
S//REL TO USA, FVEY 

Declassification Date: October 9, 2039 
Generated Date: October 9, 2014 
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(U) Source ol’Classified Information 


Source 18: (U) 600 CMT Initial Operational Capability Declaration: 

S//REL TO USA, FVEY 

Declassification Date: April 18,2039 
Generated Date: April 18, 2014 

Source 19: (U) 102 CMT Initial Operational Capability Declaration: 

S//REL TO USA, FVEY 

Declassification Date: July 1, 2039 
Generated Date: April 1, 2014 

Source 20: (U) OSD Cost Assessment and Program Evaluation, "Cyber Issue Team 

Deputy’s Management Advisory Group Comeback:” S//NF 
Declassification Date: August 31,2033 
Generated Date: December 11, 2012 

Source 21: (U) USCYBERCOM Presentation on CMF Concept of Operations: 

S//REL TO USA, FVEY 

Declassification Date: December 11, 2037 
Generated Date: January 16, 2014 

Source 22: (S//IIGL TO USA, FVEY) [ 


ARMY; USAF; USMC; (b)(1), Sec. 1.4(g) 


Declassification Date: January 12,2040 
Generated Date: January 12, 2015 

Source 23: (S//flEL TO USA, FVEY) 


ARMY; USAF; USMC: (b)(1), Sec. 1.4(g) 


Declassification Date: February 1,2039 
Generated Date: January 8, 2007 

Source 24:(U/ /F0U0) USCYBERCOM Presentation on CMF Funding: S//NF 
Declassification Date: April 1,2037 
Generated Date: November 20, 2014 

Source 25: (U) Memorandum of Agreement Between U.S. Army Intelligence and 
Security Command and 24th Air Force for Totem Stone Infrastructure and Advanced 
Cyberspace Operations Concepts, Tools, Techniques, and Technologies: S//NF 
Declassification Date: November 21, 2038 
Generated Date: December 9, 2013 

Source 26: (U) Deputy Secretary of Defense Memorandum, "Follow-on Guidance from 
the April 18, 2015, Cyber Deep Dive:" S//REL TO USA, FVEY 
Declassification Date: June 3,2040 
Generated Date: June 3, 2015 
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( U) Acronyms and Abbreviations 


(U) Acronyms and Abbreviations 


AFCYBER 

Air Forces Cyber Command 

ARCYBER 

Army Cyber Command 

CCR 

Cyber Capabilities Registry 

CMF 

Cyber Mission Force 

CMT 

Combat Mission Team 

CPT 

Cyber Protection Team 

CST 

Combat Support Team 

DISA 

Defense Information Systems Agency 

DoDIN 

DoD Information Network 

DOTMLPF-P 

Doctrine, Organization, Training, Materiel, Leadership and Education, 

Personnel, Facilities, and Policy 

FLTCYBER 

Fleet Cyber Command 

GAO 

Government Accountability Office 

JFHQ 

Joint Force Headquarters 

JWICS 

Joint Worldwide Intelligence Communications System 

MARFORCYBER 

Marine Corps Forces Cyber Command 

NMT 

National Mission Team 

NST 

National Support Team 

NIPRNet 

Non-Secure Internet Protocol Router Network 

SCIF 

Sensitive Compartmented Information Facility 

SIPRNet 

Secret Internet Protocol Router Network 

SMO 

Support to Military Operations 

USCYBERCOM 

U.S. Cyber Command 
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Whistleblower Protection 

U.S. Department of Defense 

The Whistleblower Protection Enhancement Act of 2012 requires 
the Inspector General to designate a Whistleblower Protection 
Ombudsman to educate agency employees about prohibitions 
on retaliation, and rights and remedies against retaliation for 
protected disclosures. The designated ombudsman is the DoD Hotline 
Director. For more information on your rights and remedies against 
retaliation, visit www.dodig.mil/programs/whistleblower. 


For more information about DoD IG 
reports or activities, please contact us: 

Congressional Liaison 
congressional@dodig.mil; 703.604.8324 

Media Contact 

public.affairs@dodig.mil; 703.604.8324 

Monthly Update 

dodigconnect-request@listserve.com 

Reports Mailing List 

dodig_report@listserve.com 

Twitter 

twitter.com/DoD_IG 

DoD Hotline 

dodig.mil/hotline 
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4800 Mark Center Drive 
Alexandria, VA 22350-1500 
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Defense Hotline 1.800.424.9098 
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